Agencies must make sure every system user can be uniquely identified, and that each user is authorised and authenticated every time they are given access to a system.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.